Crash in blink::maxWordFragmentWidth |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5393417932898304 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_asan_chrome_v8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: blink::maxWordFragmentWidth blink::LayoutText::computePreferredLogicalWidths blink::LayoutText::width Minimized Testcase (0.33 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96Z3Veot-VZvQl0n5R4Gp6wFbwt-EkB8Nt9VUBfaN1L3P9bTQrVAerzaozM-XQlpu5aAVk5mlbxLg9SZ8w6JzGbqbYgdOjrU93U1ddWOls3973tTET2P42fPbDAcB_X97KcnvEOrsEYQVqKCdVKeYK1U2QpmA <script> function __f_1() { document.getElementById("result").innerHTML = "PASS"; } </script> <div id="result"> </div> <style> * { writing-mode: vertical-lr; letter-spacing: 170141183460469231731687303715884105727mm;</style> <script> runTest = __f_1; runTest(); </script> Filer: pucchakayala See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
May 24 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6430569588326400 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_asan_chrome_v8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: blink::maxWordFragmentWidth blink::LayoutText::computePreferredLogicalWidths blink::LayoutText::computePreferredLogicalWidths Regressed: V8: r36355:36378 Minimized Testcase (0.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv945twL61rmNpYpmXKmvL1-Tj5Vir4o6n4gP8CzjuISLM9m9nbsVNR7J_xFXTwpjGBmnh09PfXAzSzYHgcIpCntbE0qYBJ0oAPaHH7JV5EpSxcr8p8iJT8mJ6BN6C_X3LeK3uFlftASI0al35mVtG7uV0VaSVw Filer: pucchakayala See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
May 24 2016
,
May 25 2016
ClusterFuzz has detected this issue as fixed in range 36454:36456. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5393417932898304 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_asan_chrome_v8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: blink::maxWordFragmentWidth blink::LayoutText::computePreferredLogicalWidths blink::LayoutText::width Fixed: V8: r36454:36456 Minimized Testcase (0.33 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96Z3Veot-VZvQl0n5R4Gp6wFbwt-EkB8Nt9VUBfaN1L3P9bTQrVAerzaozM-XQlpu5aAVk5mlbxLg9SZ8w6JzGbqbYgdOjrU93U1ddWOls3973tTET2P42fPbDAcB_X97KcnvEOrsEYQVqKCdVKeYK1U2QpmA <script> function __f_1() { document.getElementById("result").innerHTML = "PASS"; } </script> <div id="result"> </div> <style> * { writing-mode: vertical-lr; letter-spacing: 170141183460469231731687303715884105727mm;</style> <script> runTest = __f_1; runTest(); </script> See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 25 2016
ClusterFuzz has detected this issue as fixed in range 36454:36456. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6430569588326400 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_asan_chrome_v8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: blink::maxWordFragmentWidth blink::LayoutText::computePreferredLogicalWidths blink::LayoutText::computePreferredLogicalWidths Regressed: V8: r36355:36378 Fixed: V8: r36454:36456 Minimized Testcase (0.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv945twL61rmNpYpmXKmvL1-Tj5Vir4o6n4gP8CzjuISLM9m9nbsVNR7J_xFXTwpjGBmnh09PfXAzSzYHgcIpCntbE0qYBJ0oAPaHH7JV5EpSxcr8p8iJT8mJ6BN6C_X3LeK3uFlftASI0al35mVtG7uV0VaSVw See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||
►
Sign in to add a comment |
|||
Comment 1 by pucchakayala@chromium.org
, May 23 2016Owner: kojii@chromium.org
Status: Assigned (was: Available)